<aside>

LLMNR/NBT-NS Poisoning - from Linux

</aside>

In this phase, we will work through two different techniques side-by-side: network poisoning and password spraying.


<aside>

LLMNR = Link-Local Multicast Name Resolution

</aside>

LLMNR & NBT-NS Primer

LLMNR is based upon the Domain Name System (DNS) format and allows hosts on the same local link to perform name resolution for other hosts. It uses port 5355 over UDP natively. If LLMNR fails, the NBT-NS will be used. NBT-NS identifies systems on a local network by their NetBIOS name. NBT-NS utilizes port 137 over UDP.

The kicker here is that when LLMNR/NBT-NS are used for name resolution, ANY host on the network can reply.

⚒️Several tools can be used to attempt LLMNR & NBT-NS poisoning

Responder Responder is a purpose-built tool to poison LLMNR, NBT-NS, and MDNS, with many different functions.
Inveigh Inveigh is a cross-platform MITM platform that can be used for spoofing and poisoning attacks.
Metasploit Metasploit has several built-in scanners and spoofing modules made to deal with poisoning attacks.

⚒️Responder In Action

sudo responder -I ens224

image.png

Responder File Location → /usr/share/responder/logs

image.png

Cracking an NTLMv2 Hash With Hashcat

 hashcat -m 5600 forend_ntlmv2 /usr/share/wordlists/rockyou.txt 

<aside>

LLMNR/NBT-NS Poisoning - from Windows

</aside>

Inveigh - Overview